CVE-2020-13126 is a critical vulnerability affecting the Elementor Pro plugin for WordPress versions prior to 2.9.4, allowing authenticated attackers with Subscriber-level privileges to upload arbitrary executable files, leading to remote code execution. This flaw was exploited in the wild in May 2020, often in conjunction with CVE-2020-13125. With a CVSS score of 9.9 (CRITICAL), it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. Despite its critical severity and confirmed in-the-wild exploitation, there is no public exploit code available in Metasploit or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.9.4CPE matchmatch criteria | cpe:2.3:a:elementor:elementor_page_builder:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.